The leaky corporation.

The article focuses on information security, with the view that Corporate America is doing enough to protect its data. Several massive leakages of customer and employee data this year have left managers hurriedly peering into their labyrinthine IT systems and business processes in search of potentia...

Descripción completa

Detalles Bibliográficos
Publicado en:Economist Vol. 375; no. 8432; pp. 57 - 59
Formato: Artículo
Publicado: Economist Newspaper Limited 6/25/2005
Materias:
Acceso en línea:Ver este registro en EBSCOhost
Descripción
Sumario:The article focuses on information security, with the view that Corporate America is doing enough to protect its data. Several massive leakages of customer and employee data this year have left managers hurriedly peering into their labyrinthine IT systems and business processes in search of potential vulnerabilities. Until California recently passed a law, American firms did not have to tell anyone, even the victim, when data went astray. That may change fast: lots of proposed data-security legislation is now doing the rounds in Washington, DC. Meanwhile, the theft of information about some 40m credit-card accounts in America, disclosed on June 17th, overshadowed a hugely important decision a day earlier by America's Federal Trade Commission (FTC) that puts corporate America on notice that regulators will act if firms fail to provide adequate data security. The FTC decided to settle with BJ's Wholesale Club, a retailer whose lax data-protection practices the agency said constituted an "unfair practice that violated federal law." In its settlement with BJ's, the FTC used its broad "fairness authority" to penalise bad information-security management. For the FTC to act, this requires evidence both of substantial consumer harm and that the firm did not have reasonable grounds for failing to implement certain practices. Diana Glassman, a data protection expert, says that a useful first step would be for the boss to write to all employees reminding them of the risks and potential cost of data leakage, and asking them, before passing data to anyone else, to question whether that person truly needs, or is entitled to, it.